User Behavior Anomaly Detection for Application Layer DDoS Attacks

被引:21
|
作者
Najafabadi, Maryam M. [1 ]
Khoshgoftaar, Taghi M. [1 ]
Calvert, Chad [1 ]
Kemp, Clifford [1 ]
机构
[1] Florida Atlantic Univ, Boca Raton, FL 33431 USA
基金
美国国家科学基金会;
关键词
Application Layer DDoS Attacks; Anomaly Detection; PCA-subspace;
D O I
10.1109/IRI.2017.44
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Distributed Denial of Service (DDoS) attacks are a popular and inexpensive form of cyber attacks. Application layer DDoS attacks utilize legitimate application layer requests to overwhelm a web server. These attacks are a major threat to Internet applications and web services. The main goal of these attacks is to make the services unavailable to legitimate users by overwhelming the resources on a web server. They look valid in connection and protocol characteristics, which makes them difficult to detect. In this paper, we propose a detection method for the application layer DDoS attacks, which is based on user behavior anomaly detection. We extract instances of user behaviors requesting resources from HTTP web server logs. We apply the Principle Component Analysis (PCA) subspace anomaly detection method for the detection of anomalous behavior instances. Web server logs from a web server hosting a student resource portal were collected as experimental data. We also generated nine different HTTP DDoS attacks through penetration testing. Our performance results on the collected data show that using PCAsubspace anomaly detection on user behavior data can detect application layer DDoS attacks, even if they are trying to mimic a normal user's behavior at some level.
引用
收藏
页码:154 / 161
页数:8
相关论文
共 50 条
  • [41] ConnectionScore: a statistical technique to resist application-layer DDoS attacks
    Beitollahi, Hakem
    Deconinck, Geert
    JOURNAL OF AMBIENT INTELLIGENCE AND HUMANIZED COMPUTING, 2014, 5 (03) : 425 - 442
  • [42] ConnectionScore: a statistical technique to resist application-layer DDoS attacks
    Hakem Beitollahi
    Geert Deconinck
    Journal of Ambient Intelligence and Humanized Computing, 2014, 5 : 425 - 442
  • [43] Alleviation of Application Layer DDoS Attacks Using Data Specification Module
    Saravanan, R.
    Vigneswari, K.
    INTERNATIONAL JOURNAL OF COMPUTER SCIENCE AND NETWORK SECURITY, 2013, 13 (04): : 29 - 34
  • [44] DDoS Attacks Detection with AutoEncoder
    Yang, Kun
    Zhang, Junjie
    Xu, Yang
    Chao, Jonathan
    NOMS 2020 - PROCEEDINGS OF THE 2020 IEEE/IFIP NETWORK OPERATIONS AND MANAGEMENT SYMPOSIUM 2020: MANAGEMENT IN THE AGE OF SOFTWARIZATION AND ARTIFICIAL INTELLIGENCE, 2020,
  • [45] An Anomaly-Based Method for DDoS Attacks Detection using RBF Neural Networks
    Karimazad, Reyhaneh
    Faraahi, Ahmad
    NETWORK AND ELECTRONICS ENGINEERING, 2011, 11 : 44 - 48
  • [46] Application layer DDoS detection using clustering analysis
    Ye, Chengxu
    Zheng, Kesong
    She, Chuyu
    PROCEEDINGS OF 2012 2ND INTERNATIONAL CONFERENCE ON COMPUTER SCIENCE AND NETWORK TECHNOLOGY (ICCSNT 2012), 2012, : 1038 - 1041
  • [47] Application Layer DDOS Attack Detection and Defense Methods
    Sreenivasarao, Sadhu
    PROCEEDINGS OF EMERGING TRENDS AND TECHNOLOGIES ON INTELLIGENT SYSTEMS (ETTIS 2021), 2022, 1371 : 1 - 12
  • [48] Detection of Application-Layer DDoS by Clustering Algorithm
    She, Chuyu
    Wen, Wushao
    Lin, Zaihua
    Zheng, Kesong
    PROCEEDINGS OF THE 2016 2ND INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE AND INDUSTRIAL ENGINEERING (AIIE 2016), 2016, 133 : 102 - 104
  • [49] Detection of Application-Layer DDoS Attacks Produced by Various Freely Accessible Toolkits Using Machine Learning
    Sharif, Dyari Mohammed
    Beitollahi, Hakem
    Fazeli, Mahdi
    IEEE ACCESS, 2023, 11 : 51810 - 51819
  • [50] Transport and Application Layer DDoS Attacks Detection to IoT Devices by Using Machine Learning and Deep Learning Models
    Almaraz-Rivera, Josue Genaro
    Perez-Diaz, Jesus Arturo
    Cantoral-Ceballos, Jose Antonio
    SENSORS, 2022, 22 (09)